Guest anchoring requires mobility tunnels to be established between the foreign and anchor WLCs. For these tunnels to function, the firewall must allow specific ports for communication. UDP port 16666 is the port used for mobility traffic in Cisco wireless networks, and if it is not allowed through the firewall, MPING and mobility tunnels will fail. References: CCNP Enterprise Wireless Design ENWLSD 300-425 and Implementation ENWLSI 300-430 Official Cert Guide Premium Edition and Practice
